Skip to content
You can now search across every topic, entity and event.What's new
Rockwell Automation
OrganisationUS

Rockwell Automation

A US industrial automation and control-systems manufacturer.

Rockwell Automation, a US industrial-control-systems manufacturer, published advisory SD1790 on 30 July 2026 covering MicroLogix 1100 and 1400 controllers, revised the following day.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Why did Rockwell issue recovery guidance instead of a vulnerability patch?

Timeline for Rockwell Automation

#12 29 Jul

Published SD1790 recovery guidance for locked-out MicroLogix controllers on 30 July

Cybersecurity: Threats and Defences: The alert's citations predate the alert
View full timeline →

Background

Rockwell Automation is a US manufacturer of industrial automation and control-systems equipment, supplying programmable logic controllers and related hardware used to run manufacturing, utility and other operational-technology environments.

On 30 July 2026 the company published advisory SD1790, covering its MicroLogix 1100 and 1400 controller lines, revising it the following day. The advisory carries no attached CVE and is operational recovery guidance for a locked device, not a patch for a vulnerability; a CISA alert on the matter cited older NCSC operational-technology guidance alongside it, a chronology worth noting precisely rather than implying coordinated new action.

This page will be updated once further detail on the underlying incident, if any, or a formal vulnerability disclosure becomes available.

Common Questions
What is Rockwell Automation's SD1790 advisory?
SD1790 is Rockwell's recovery guidance, published 30 July 2026 and revised the next day, telling operators how to regain access to MicroLogix 1100 and 1400 controllers that attackers locked by changing passwords; it carries no CVE and is not a patch.Source: Rockwell Automation advisory SD1790
Does SD1790 fix a vulnerability in MicroLogix controllers?
No. Rockwell states explicitly that SD1790 is operational recovery guidance, not a vulnerability disclosure, and no CVE identifier is attached.Source: Rockwell Automation advisory SD1790
Which MicroLogix models does advisory SD1790 cover?
SD1790 covers both the MicroLogix 1100 and 1400 controller families, while CISA's alert names only the 1400.Source: Rockwell Automation advisory SD1790
Why did Rockwell Automation publish SD1790?
Attackers locked operators out of internet-exposed MicroLogix controllers at water and other facilities by changing device passwords; SD1790 tells engineers how to recover access.Source: Rockwell Automation advisory SD1790